Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-23 Thread Simone Giannecchini
+0 Simone. --- Ing. Simone Giannecchini GeoSolutions S.A.S. Founder Via Poggio alle Viti 1187 55054  Massarosa (LU) Italy phone: +39 0584962313 fax:      +39 0584962313 mob:    +39 333 8128928 http://www.geo-solutions.it http://geo-solutions.

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-22 Thread Mark Leslie
On 22 December 2010 20:36, Andrea Aime wrote: > On Tue, Dec 21, 2010 at 6:10 AM, Mark Leslie wrote: >> >> I'm always keen to see enhancements to security features, and this >> seems a solid step in the right direction.  Can I just clarify that >> backwards compatibility will be handled by wrappin

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-22 Thread Andrea Aime
On Tue, Dec 21, 2010 at 11:33 PM, Chris Holmes wrote: > +1 on the GSIP, as long as Mark's backwards compatibility concerns are > addressed, though I'm pretty sure they are. This sounds like a solid step > towards an awesome security system. > > Yep yep, definitely want to keep backwards compatib

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-22 Thread Andrea Aime
On Tue, Dec 21, 2010 at 10:10 PM, Rob Atkinson wrote: > looks like a good idea. > > my first thought was how does this relate to GeoXACML - and I see you > have been thinking about this - is it possible to map out what > GeoXACML would require and how this proposal supports this? If I was > an exp

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-22 Thread Andrea Aime
On Tue, Dec 21, 2010 at 6:10 AM, Mark Leslie wrote: > I'm always keen to see enhancements to security features, and this > seems a solid step in the right direction. Can I just clarify that > backwards compatibility will be handled by wrapping implementations of > DataAccessManager (the compatib

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-22 Thread Andrea Aime
On Tue, Dec 21, 2010 at 9:02 PM, Jody Garnett wrote: > Looks good Andrea. +1 with a couple of questions > > 1) The only wrinkle I can see is the use of List for > VectorAccessLimits when used with app-schema xpaths. > Ah, yeah, sounds like a good idea. Wondering, is Name good enough? Does it have

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-21 Thread Chris Holmes
+1 on the GSIP, as long as Mark's backwards compatibility concerns are addressed, though I'm pretty sure they are. This sounds like a solid step towards an awesome security system. Nice paper too, I'll definitely be pointing people to it to explain why all the proxy projects aren't that great. O

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-21 Thread Rob Atkinson
looks like a good idea. my first thought was how does this relate to GeoXACML - and I see you have been thinking about this - is it possible to map out what GeoXACML would require and how this proposal supports this? If I was an expert in GeoXACML I'd do this myself - but I'd then be in the dark a

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-21 Thread Jody Garnett
Looks good Andrea. +1 with a couple of questions 1) The only wrinkle I can see is the use of List for VectorAccessLimits when used with app-schema xpaths. 2) I also wondered about the RasterLimits; do you not need a ParameterDescriptor in order to define the allowable range (sorry if I am rusty

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-20 Thread Mark Leslie
I'm always keen to see enhancements to security features, and this seems a solid step in the right direction. Can I just clarify that backwards compatibility will be handled by wrapping implementations of DataAccessManager (the compatibility section hasn't been updated from the template). -- Mark

Re: [Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-20 Thread Alessio Fabiani
+0 here --- Ing. Alessio Fabiani Founder / CTO GeoSolutions S.A.S. GeoSolutions S.A.S. Via Poggio alle Viti 1187 55054 Massarosa (LU) Italy phone: (+39) 0584 96.23.13 fax: (+39) 0584 96.23.13 mobile:(+39) 349 82.27.000 http://www.geo-solu

[Geoserver-devel] GSIP 57 - Improving GeoServer authorization framework

2010-12-20 Thread Andrea Aime
Hi, following up last week mail I prepared a GSIP to improve the authorization framework built into the GeoServer catalog: http://geoserver.org/display/GEOS/GSIP+57+-+Improving+GeoServer+authorization+framework Opinions and votes welcomed! Cheers Andrea PS: Also, at GeoSolutions we spent a bit o